CVE-2023-31210: Privilege escalation in agent via LD_LIBRARY_PATH

Published Dec 13, 2023
·
Updated

Usage of user controlled LDLIBRARYPATH in agent in Checkmk 2.2.0p10 up to 2.2.0p16 allows malicious Checkmk site user to escalate rights via injection of malicious libraries

Affected Software

7 affected components
CheckMK Checkmk=2.2.0-p10
CheckMK Checkmk=2.2.0-p11
CheckMK Checkmk=2.2.0-p12
CheckMK Checkmk=2.2.0-p13
CheckMK Checkmk=2.2.0-p14
CheckMK Checkmk=2.2.0-p15
CheckMK Checkmk=2.2.0-p16

Event History

Dec 13, 2023
CVE Published
08:26 AM
Data Sourced
08:26 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2023-31210?

CVE-2023-31210 has been classified as a high severity vulnerability due to the potential for privilege escalation.

2

How do I fix CVE-2023-31210?

To mitigate CVE-2023-31210, it is recommended to update Checkmk to a fixed version, such as 2.2.0p17 or later.

3

Who is impacted by CVE-2023-31210?

CVE-2023-31210 affects users of Checkmk versions 2.2.0p10 through 2.2.0p16.

4

What kind of exploit is associated with CVE-2023-31210?

CVE-2023-31210 allows a malicious Checkmk site user to escalate their privileges by injecting malicious libraries.

5

Can CVE-2023-31210 be exploited remotely?

Yes, CVE-2023-31210 may be exploited by an authenticated user on the same Checkmk site.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203